British Airways hack explained
Content:
Original link: This $17B airline stored their admin password in a plain text file. A hacker found it... and stole the data of 400,000+ customers. / LinkedIn / Chris Cooper.
- login and password stolen from contractor
- no MFA
- credential used to login
- found an admin password in a text file
- payment system had debug enabled where it logged credit card info in plain text
- hacker stole logged credit card info
- web site had JS vulnerability
- hacker used vulnerability to modify web site to send payment info to hackers in real time
Total fuckup!!
Comments: